Impact
This vulnerability resides in the JobLogController.java component of the alldata framework and allows an attacker to manipulate the executorAddress argument to perform a path traversal. By controlling this input the attacker can read files outside the intended directory, potentially exposing sensitive configuration or system files. The flaw is a classic example of CWE‑22 and can lead to confidentiality compromise if exploited successfully.
Affected Systems
The flaw affects alldatacenter’s alldata application up to version 0.6.8. Any installation of this software that has not been updated beyond 0.6.8 is at risk.
Risk and Exploitability
The CVSS score of 6.9 categorizes the weakness as moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, but an exploit has already been published and noted as remotely actionable. The likely attack vector is remote, as the flaw can be triggered through a web request that supplies a crafted executorAddress value.
OpenCVE Enrichment